⤷ Title: XWorm’s Shape-Shifting Arsenal: RAT Evolves to Deliver LockBit Ransomware, Evades Detection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 01:33:36 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #DLL side_loading #ETW Tampering #LockBit #malware #Process injection #ransomware #rat #Remote Access Trojan #XWorm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 07 Jul 2025 01:33:36 +0000
════════════════════════
⌗ Tags: #Malware #AMSI Bypass #cybersecurity #DLL side_loading #ETW Tampering #LockBit #malware #Process injection #ransomware #rat #Remote Access Trojan #XWorm
Daily CyberSecurity
XWorm's Shape-Shifting Arsenal: RAT Evolves to Deliver LockBit Ransomware, Evades Detection
Splunk uncovers XWorm's evolution: a modular RAT now delivering LockBit ransomware. It uses flexible delivery, AMSI/ETW bypasses, and process injection to evade detection.
⤷ Title: COMmander: Unmasking Hidden Threats in Windows with Deep RPC/COM Monitoring
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 16 Jul 2025 03:11:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #COM #cybersecurity #ETW #Low_Level Monitoring #malware analysis #RPC #security tool #Threat Detection #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 16 Jul 2025 03:11:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #COM #cybersecurity #ETW #Low_Level Monitoring #malware analysis #RPC #security tool #Threat Detection #Windows Security
Penetration Testing Tools
COMmander: Unmasking Hidden Threats in Windows with Deep RPC/COM Monitoring
COMmander is a lightweight, practical tool that monitors deep-seated RPC and COM activities in Windows, designed to detect subtle, invisible threats that bypass traditional security.
⤷ Title: Evading ETW Techniques ( written in C):
════════════════════════
𐀪 Author: Zanebilal
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 18:41:39 GMT
════════════════════════
⌗ Tags: #etw #evasion #windows_internals #cybersecurity
════════════════════════
𐀪 Author: Zanebilal
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 18:41:39 GMT
════════════════════════
⌗ Tags: #etw #evasion #windows_internals #cybersecurity
Medium
Evading ETW Techniques ( written in C):
before we begin : the code discussed in this blog is evaluable in my GitHub repo : https://github.com/Zanebilal/ETW-Evasion
⤷ Title: JonMon-Lite: The Remote Agentless EDR Proof-of-Concept for ETW Trace Monitoring
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 04:22:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Agentless #CybersecurityTool #DataCollectorSet #EDR #ETW #JonMonLite #ProofOfConcept #WindowsMonitoring
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 17 Nov 2025 04:22:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Agentless #CybersecurityTool #DataCollectorSet #EDR #ETW #JonMonLite #ProofOfConcept #WindowsMonitoring
Penetration Testing Tools
JonMon-Lite: The Remote Agentless EDR Proof-of-Concept for ETW Trace Monitoring
JonMon-Lite is a proof-of-concept "Remote Agentless EDR" that creates an ETW Trace Session to monitor Windows events, including Process Creation, DPAPI, and AMSI activity.
⤷ Title: COMmander: Lightweight C# Tool Boosts Defensive RPC/COM Telemetry
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 10:15:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #C++ #COM #Commander #cyber defense #ETW #RPC #security tool #Telemetry #Threat Detection #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 20 Nov 2025 10:15:28 +0000
════════════════════════
⌗ Tags: #Open Source Tool #C++ #COM #Commander #cyber defense #ETW #RPC #security tool #Telemetry #Threat Detection #windows
Penetration Testing Tools
COMmander: Lightweight C# Tool Boosts Defensive RPC/COM Telemetry
COMmander is a new, lightweight C# tool that leverages the Windows RPC ETW provider to enrich defensive telemetry, enabling granular detection of RPC/COM events.
⤷ Title: BamboozlEDR: New Tool Generates Realistic ETW Events to Test EDR Detection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:49:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BamboozlEDR #blue team #EDR #ETW #Event Tracing for Windows #Red Team #research #security testing #TUI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:49:34 +0000
════════════════════════
⌗ Tags: #Open Source Tool #BamboozlEDR #blue team #EDR #ETW #Event Tracing for Windows #Red Team #research #security testing #TUI
Penetration Testing Tools
BamboozlEDR: New Tool Generates Realistic ETW Events to Test EDR Detection
BamboozlEDR is a new ETW event generation tool with a TUI interface. It generates realistic security events to test and validate EDR detection capabilities and security monitoring solutions.
⤷ Title: LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:06:57 +0000
════════════════════════
⌗ Tags: #Malware #anti_forensics #Cross_Platform #Cybercrime #ESXi #ETW Blinding #LockBit 5.0 #Operation Cronos #ransomware
Daily CyberSecurity
LockBit 5.0 Resurfaces Stronger: New Variant Blinds Defenders by Disabling Windows ETW for Stealth Encryption
Despite takedown, LockBit 5.0 resurges as a cross-platform threat. The new variant blinds Windows Event Tracing (ETW), uses Invisible Mode for stealth encryption, and overwrites free disk space.
⤷ Title: Founding: The Next-Gen Loader Generator for Advanced Evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 03:21:55 +0000
════════════════════════
⌗ Tags: #Open Source Tool #AMSI Bypass #Cybersecurity 2025 #ETW Blinding #Founding #Indirect Syscalls #Malware Evasion #Obfuscation #red teaming #Sandbox Evasion #shellcode
Information Security News
Founding: The Next-Gen Loader Generator for Advanced Evasion
Founding is a tool that processes shellcode in .bin, .exe, or .dll formats, applying advanced obfuscation or encryption techniques to generate stealthy binaries with sophisticated execution method…
⤷ Title: Ghost in the Machine: Sanctum EDR Uses Rust and “Ghost Hunting” to Unmask Stealth Malware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 04:06:04 +0000
════════════════════════
⌗ Tags: #Open Source Tool #0xflux #Alt Syscalls #Cybersecurity 2026 #endpoint security #ETW Threat Intelligence #Ghost Hunting #Kernel Driver #Malware Detection #Rust #Sanctum EDR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 07 Jan 2026 04:06:04 +0000
════════════════════════
⌗ Tags: #Open Source Tool #0xflux #Alt Syscalls #Cybersecurity 2026 #endpoint security #ETW Threat Intelligence #Ghost Hunting #Kernel Driver #Malware Detection #Rust #Sanctum EDR
Information Security News
Ghost in the Machine: Sanctum EDR Uses Rust and “Ghost Hunting” to Unmask Stealth Malware
Sanctum is going to be an EDR, built in Rust, designed to perform the job of both an antivirus (AV) and Endpoint Detection and Response (EDR). Structure Crate Description driver Contains the code …
⤷ Title: Deep Kernel Visibility: Unveiling Surveyor, the Ultimate Windows Profiling Tool
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 10 Jan 2026 10:42:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Driver Analysis #EDR Detection #ETW #Forensics #Infosec #Kernel Callbacks #Memory Forensics #Surveyor #Symbol Resolution #Sysinternals #Windows Kernel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 10 Jan 2026 10:42:02 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Driver Analysis #EDR Detection #ETW #Forensics #Infosec #Kernel Callbacks #Memory Forensics #Surveyor #Symbol Resolution #Sysinternals #Windows Kernel
Information Security News
Deep Kernel Visibility: Unveiling Surveyor, the Ultimate Windows Profiling Tool
Surveyor Advanced Windows kernel analysis and system profiling tool. Provides comprehensive visibility into kernel callbacks, ETW sessions, driver analysis, and system state through both userland …